CVE-2021-29922
published 2021-08-07CVE-2021-29922: library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in…
PriorityP350critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
2.62%
83.7th percentile
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rustc | < rustc 1.53.0+dfsg1-1 (bookworm) | rustc 1.53.0+dfsg1-1 (bookworm) |
| rust-lang | rust | < 1.53.0 | 1.53.0 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rust: incorrect parsing of extraneous zero characters at the beginning of an IP address string
vendor_redhat·2021-03-29·CVSS 9.1
CVE-2021-29922 [CRITICAL] CWE-20 rust: incorrect parsing of extraneous zero characters at the beginning of an IP address string
rust: incorrect parsing of extraneous zero characters at the beginning of an IP address string
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
A flaw was found in rust. Extraneous zero characters at the beginning of an IP address string are not properly considered which can allow an attacker to bypass IP-based access controls. The highest threat from this vulnerability is to data confidentiality and integrity.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security c
Debian
CVE-2021-29922: rustc - library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider e...
vendor_debian·2021·CVSS 9.1
CVE-2021-29922 [CRITICAL] CVE-2021-29922: rustc - library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider e...
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
Scope: local
bookworm: resolved (fixed in 1.53.0+dfsg1-1)
bullseye: open
forky: resolved (fixed in 1.53.0+dfsg1-1)
sid: resolved (fixed in 1.53.0+dfsg1-1)
trixie: resolved (fixed in 1.53.0+dfsg1-1)
GHSA
GHSA-g9v3-gh27-qjh3: library/std/src/net/parser
ghsa_unreviewed·2022-05-24
CVE-2021-29922 [CRITICAL] GHSA-g9v3-gh27-qjh3: library/std/src/net/parser
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
OSV
CVE-2021-29922: library/std/src/net/parser
osv·2021-08-07·CVSS 9.1
CVE-2021-29922 [CRITICAL] CVE-2021-29922: library/std/src/net/parser
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
No detection rules found.
No public exploits indexed.
https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudishttps://doc.rust-lang.org/beta/std/net/struct.Ipv4Addr.htmlhttps://github.com/rust-lang/rust/issues/83648https://github.com/rust-lang/rust/pull/83652https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-015.mdhttps://security.gentoo.org/glsa/202210-09https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudishttps://doc.rust-lang.org/beta/std/net/struct.Ipv4Addr.htmlhttps://github.com/rust-lang/rust/issues/83648https://github.com/rust-lang/rust/pull/83652https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-015.mdhttps://security.gentoo.org/glsa/202210-09
2021-08-07
Published